mirror of
https://github.com/DarkflameUniverse/DarkflameServer.git
synced 2026-10-02 19:03:43 +00:00
299 lines
13 KiB
INI
299 lines
13 KiB
INI
# Web Dashboard Configuration
|
|
|
|
# The port to listen on for HTTP/WebSocket connections
|
|
port=2006
|
|
|
|
# UDP port for the dashboard's connection to the master server (the next port is used too). It must not clash with
|
|
# another server's ports: auth uses 1500-1501, chat 2005-2006, worlds 3000 and up.
|
|
net_port=2010
|
|
|
|
# The IP address to bind to
|
|
# Use 127.0.0.1 for localhost only (recommended for security)
|
|
# Use 0.0.0.0 to allow external access; prefer a reverse proxy with HTTPS and secure_cookies=1
|
|
listen_ip=127.0.0.1
|
|
|
|
# How often to broadcast updates to connected clients (in milliseconds)
|
|
broadcast_interval=2000
|
|
|
|
# Minimum GM level required to access the dashboard (default: 0 = any user)
|
|
min_dashboard_gm_level=0
|
|
|
|
# Secret used to sign login tokens (at least 32 characters). If empty, a random secret is generated
|
|
# on first start and stored in dashboard_jwt_secret next to the binary. Changing it signs everyone out.
|
|
jwt_secret=
|
|
|
|
# Set to 1 when the dashboard is served over HTTPS (e.g. behind a reverse proxy) so the session
|
|
# cookie is only ever sent over encrypted connections.
|
|
secure_cookies=0
|
|
|
|
# Set to 1 if a reverse proxy sits in front of the dashboard, so rate limits use the client's address
|
|
# from X-Forwarded-For instead of the proxy's. Only enable this when the dashboard is not reachable directly.
|
|
behind_proxy=0
|
|
|
|
# Threads converting the game client's models for the 3D views, so the dashboard keeps answering meanwhile.
|
|
# 0 picks half the CPU cores (2 to 4). Read at startup.
|
|
scenery_workers=0
|
|
|
|
# Allow players to create accounts at /register
|
|
allow_registration=0
|
|
|
|
# Require a valid play key to register (keys are managed on the Play Keys page)
|
|
registration_requires_play_key=1
|
|
|
|
# Allow GM 8+ to replace a character's XML from the character page. The owner is disconnected first.
|
|
enable_char_xml_upload=0
|
|
|
|
# ---- Email (password resets and address confirmation) ----
|
|
# Email is enabled once smtp_host, smtp_from_address and dashboard_url are all set.
|
|
|
|
# Public address of the dashboard, used for links in emails, e.g. https://dashboard.example.com
|
|
# Links are never built from the request's Host header, so this must be set explicitly.
|
|
dashboard_url=
|
|
|
|
# Where the dashboard reaches the UGC server (normally on the same machine) for its status and the files it made;
|
|
# the dashboard's pages load them through the dashboard, so the browser never needs to reach the UGC server.
|
|
# Empty: http://127.0.0.1:2008
|
|
ugc_internal_url=
|
|
|
|
# The UGC server's public address, only for "open on the UGC server" links, e.g. https://ugc.example.com. Empty: none.
|
|
ugc_public_url=
|
|
|
|
# SMTP server and port. Typical: 587 with starttls, or 465 with tls.
|
|
smtp_host=
|
|
smtp_port=587
|
|
|
|
# starttls, tls (implicit TLS from the first byte) or none (only for a relay on the same machine)
|
|
smtp_security=starttls
|
|
|
|
# How to sign in to the SMTP server: password, or oauth2 (required for Microsoft 365, recommended for Gmail)
|
|
smtp_auth=password
|
|
|
|
# Login for the SMTP server. Credentials are never sent without TLS.
|
|
# With oauth2, smtp_username is the mailbox address (defaults to smtp_from_address) and no password is used.
|
|
smtp_username=
|
|
smtp_password=
|
|
|
|
# ---- OAuth2 (smtp_auth=oauth2) ----
|
|
# microsoft, google or custom. microsoft and google fill in the URLs, scopes and SMTP server for you.
|
|
smtp_oauth2_provider=
|
|
# From your app registration (Azure portal / Google Cloud console)
|
|
smtp_oauth2_client_id=
|
|
smtp_oauth2_client_secret=
|
|
# authorization_code: an operator clicks "Connect mail account" on their account page once.
|
|
# client_credentials: Microsoft 365 app-only sending (SMTP.SendAsApp); needs smtp_oauth2_tenant.
|
|
smtp_oauth2_grant=authorization_code
|
|
# Microsoft only: your tenant ID or domain (defaults to common)
|
|
smtp_oauth2_tenant=
|
|
# Only needed for provider=custom
|
|
smtp_oauth2_authorize_url=
|
|
smtp_oauth2_token_url=
|
|
smtp_oauth2_scope=
|
|
|
|
# Sender shown to players
|
|
smtp_from_address=
|
|
smtp_from_name=DarkflameServer
|
|
|
|
# Server certificates are checked against the system's trusted certificates. Point this at a PEM bundle to
|
|
# trust a private CA instead. Set smtp_verify_certificate=0 only for local testing.
|
|
smtp_ca_file=
|
|
smtp_verify_certificate=1
|
|
|
|
# Seconds to wait for the SMTP server
|
|
smtp_timeout=20
|
|
|
|
# Require an email address when registering (only when email is enabled)
|
|
registration_requires_email=0
|
|
|
|
# ---- Two-factor login ----
|
|
# Staff at or above this GM level must set up two-factor login (authenticator app) before using the dashboard.
|
|
# 0 turns the requirement off; anyone can still turn it on for their own account.
|
|
require_2fa_gm_level=0
|
|
# Name shown in authenticator apps
|
|
totp_issuer=DarkflameServer
|
|
# 64 hex characters used to encrypt two-factor secrets. Leave empty to generate dashboard_totp_key next to the
|
|
# server; back that file up with the database, or everyone's two-factor login stops working.
|
|
totp_key=
|
|
|
|
# ---- Economy checks (run each night for the day before; schedule and on/off on the dashboard's Tasks page) ----
|
|
# Flag a character who earned more than this many times the median player, and more than the minimum, in a day
|
|
anomaly_coin_multiplier=20
|
|
anomaly_coin_minimum=100000
|
|
# Flag an item created more than this many times its usual daily amount, and more than the minimum, in a day
|
|
anomaly_item_multiplier=10
|
|
anomaly_item_minimum=200
|
|
# Also scan every character for duplicated items each night (reads all character data)
|
|
economy_duplicate_scan=1
|
|
|
|
# ---- Economy ledger size ----
|
|
# Daily detail older than this many days is merged into one row per month
|
|
economy_detail_days=180
|
|
economy_map_days=90
|
|
# Trades and mail older than this many days are deleted
|
|
economy_transfer_days=730
|
|
|
|
# ---- Log retention, in days (0 keeps everything). Pruned by the log_pruning task, once a day by default. ----
|
|
log_activity_days=365
|
|
log_command_days=365
|
|
log_audit_days=730
|
|
log_cheat_detection_days=365
|
|
# Finished runs of scheduled tasks, with their logs
|
|
log_task_days=90
|
|
|
|
# ---- Permissions ----
|
|
# Change the lowest GM level (1-9) allowed to do something on the dashboard, e.g. permission_accounts_ban=3.
|
|
# Every permission and its name is listed on the dashboard's Permissions page, where GM 9 can also change them;
|
|
# a level set there beats this file.
|
|
|
|
# ---- Dashboard sign-in ----
|
|
# Password reset with recovery codes: Players with two-factor login can choose a new password on /forgot_password with a
|
|
# code from their authenticator app and one of their recovery codes, no email needed.
|
|
password_reset_recovery_codes=1
|
|
|
|
# ---- OAuth2 sign-in ----
|
|
# Refresh token: Set by Connect mail account; only set it by hand for a token from elsewhere. Read when the server
|
|
# starts.
|
|
smtp_oauth2_refresh_token=
|
|
|
|
# ---- Tools ----
|
|
# Challenge milestones: Percentages of a community challenge announced in game as it gets there, e.g. 25,50,75
|
|
# (completing it is always announced).
|
|
challenge_milestones=25,50,75,100
|
|
|
|
# ---- Public pages ----
|
|
# Public server status: The page at /status, its JSON at /api/public/status (for server lists) and a widget for other
|
|
# sites.
|
|
public_status=0
|
|
# Server name: Shown on the status page and widget.
|
|
public_server_name=DarkflameServer
|
|
# Players per world: How many players are in each world.
|
|
public_status_players=1
|
|
# Names of players online: Character names (never staff, never account names) by world.
|
|
public_status_names=0
|
|
# Uptime: How long the server has been up, and how much of the last day and week.
|
|
public_status_uptime=1
|
|
# Server health: Whether login and chat are up, and how many worlds are running.
|
|
public_status_health=1
|
|
# Leaderboard places: The top places of every leaderboard. 0 leaves leaderboards out. (places)
|
|
public_status_leaderboard_top=3
|
|
# Community challenges: Public challenges that are running or finished in the last week, with their progress.
|
|
public_status_challenges=1
|
|
# Live events: Live events running now (their title, where, and until when).
|
|
public_status_events=1
|
|
# Widget for other sites: A small page at /status/widget other sites may show in an iframe.
|
|
public_status_widget=1
|
|
# Refresh every: The status is worked out at most this often, however many people ask. (seconds)
|
|
public_status_cache_seconds=60
|
|
# Property showcase for everyone: Let people who aren't signed in browse approved public properties at /showcase.
|
|
# Signed-in players need the showcase_view permission.
|
|
showcase_public=0
|
|
|
|
# ---- Metrics ----
|
|
# API key rate limit: Requests a minute an API key may make unless the key sets its own limit (up to 6000). (/min)
|
|
api_key_rate_limit=120
|
|
# Metrics endpoint: Off: /metrics answers 404. On: scrapers send an API token of an account with metrics_view, or the
|
|
# token below.
|
|
metrics_enabled=0
|
|
# Scraper token: A shared secret scrapers may send as Authorization: Bearer instead of an API token. At least 16
|
|
# characters; empty: API tokens only.
|
|
metrics_token=
|
|
# Allowed addresses: Comma separated addresses or IPv4 ranges (10.0.0.0/8) that may fetch metrics. Empty: any.
|
|
metrics_allowed_ips=
|
|
# Refresh every: Metrics are worked out at most this often, however often they are fetched. (seconds)
|
|
metrics_cache_seconds=10
|
|
|
|
# ---- Strikes ----
|
|
# Strikes count for: Older strikes stay on the account's record but no longer count. 0: they always count. (days)
|
|
strike_expiry_days=0
|
|
# Warn at: When an account reaches this many active strikes it gets a warning, shown to the player if they're online. 0:
|
|
# never. (strikes)
|
|
strike_warn_at=0
|
|
# Mute at: ...is muted for the days below. 0: never. (strikes)
|
|
strike_mute_at=0
|
|
# Mute for (days)
|
|
strike_mute_days=3
|
|
# Ban at: ...is banned for the days below. 0: never. (strikes)
|
|
strike_ban_at=0
|
|
# Ban for: 0: permanently. (days)
|
|
strike_ban_days=7
|
|
|
|
# ---- AI moderator helper ----
|
|
# AI moderator helper: Off: the Suggest buttons say the helper is off and nothing is sent.
|
|
ai_helper_enabled=0
|
|
# Claude API key: From console.anthropic.com. Never shown back or logged.
|
|
claude_api_key=
|
|
# API address: Only change it for a proxy or a local test server (http:// only for this machine).
|
|
claude_api_base=https://api.anthropic.com
|
|
# Model: Any model ID works. claude-sonnet-5 is a good balance; claude-haiku-4-5-20251001 is cheaper, claude-opus-5-5
|
|
# more careful.
|
|
claude_model=claude-sonnet-5
|
|
# Hold answers to a schema: Ask the API for JSON of the expected shape (structured outputs). Turn off only if a model
|
|
# refuses it; answers are checked either way.
|
|
claude_structured_output=1
|
|
# Server rules: Your code of conduct, as players know it. Sent with every request so suggestions follow your rules.
|
|
ai_helper_rules=
|
|
# Time out after: Per try; failed tries (busy API, network) are retried up to three times. (seconds)
|
|
ai_helper_timeout=60
|
|
# Longest answer: max_tokens per request: caps what one suggestion can cost. (tokens)
|
|
ai_helper_max_tokens=2000
|
|
# Requests per minute: For the whole dashboard. (requests)
|
|
ai_helper_per_minute=5
|
|
# Requests per day: For the whole dashboard, per UTC day. Asking about the same thing again reuses the stored suggestion
|
|
# and costs nothing. (requests)
|
|
ai_helper_per_day=200
|
|
# Chat around the item: How far before and after a report or message the player's chat is included. (minutes)
|
|
ai_helper_chat_minutes=10
|
|
|
|
# ---- Backups ----
|
|
# Backup folder: Relative to the server binaries unless absolute.
|
|
backup_folder=backups
|
|
# Backups to keep: Older backups are deleted after each new one. 0 keeps them all. (backups)
|
|
backup_keep=7
|
|
# mysqldump program: The mysqldump (or mariadb-dump) to run.
|
|
backup_mysqldump=mysqldump
|
|
|
|
# ---- Logs ----
|
|
# Chat log (days)
|
|
log_chat_days=30
|
|
# Login addresses: Addresses an account hasn't logged in from for this long are forgotten. (days)
|
|
log_login_address_days=90
|
|
# Client system info: System descriptions clients sent at login that haven't been seen for this long are forgotten. (days)
|
|
log_client_sysinfo_days=90
|
|
# Server health history: Minute-by-minute player counts and uptime. (days)
|
|
health_days=30
|
|
# Server traffic history: Minute-by-minute packets, bytes and HTTP requests of every server (Diagnostics). The last hour
|
|
# at one second is only kept in memory. (days)
|
|
traffic_days=30
|
|
|
|
# ---- Log bundles ----
|
|
# At most: How much log text (before compression) one download may hold. Bundles are built in the system's temporary
|
|
# folder and deleted once sent. (MB)
|
|
log_bundle_max_mb=512
|
|
|
|
# ---- Player movement ----
|
|
# Record player movement: Keeps a player's position every few seconds while they move, and every 30 seconds while they
|
|
# stand still.
|
|
position_history=1
|
|
# Record every: While a player moves. Less often keeps the table smaller; replays then move in straighter lines.
|
|
# (seconds)
|
|
position_history_seconds=5
|
|
# Keep movement for: About 17,000 rows per player online around the clock per day at 5 seconds. (days)
|
|
position_history_days=3
|
|
|
|
# ---- Message inspector ----
|
|
# Keep captures for: 0: no age limit. (days)
|
|
inspector_session_days=30
|
|
# At most: When all saved captures together take more, the oldest are deleted. A busy 15 minute capture can take 50 MB.
|
|
# 0: no size limit. (MB)
|
|
inspector_max_mb=1024
|
|
|
|
# ---- Character history ----
|
|
# Snapshots: Older snapshots are deleted, but each character keeps its newest few (below). (days)
|
|
snapshot_days=90
|
|
# Always keep per character (snapshots)
|
|
snapshot_keep=10
|
|
|
|
# ---- Packet capture ----
|
|
# Capture files: Folder for packet capture files, relative to the server binaries. Captures are player data: keep it out
|
|
# of any repository.
|
|
capture_dir=captures
|